logo

NDSS 2025 – Compiled Models, Built-In Exploits

ID: f489a908-04ea-5d4c-a3c4-5989776605fd

STIX ID: report--f489a908-04ea-5d4c-a3c4-5989776605fd

Feed Name: Security Boulevard

Date Published: 2026-01-18

Date Updated: 2026-04-22

Author: Marc Handelman

...
...

Research presented at NDSS 2025 demonstrates that Rowhammer-driven bit-flip attacks against compiled DNN executables can severely degrade model accuracy by flipping as few as ~1–2 bits, by exploiting publicly known model structures embedded in executable code rather than confidential weights. The attacks are pervasive, transferable, evade existing defenses (including for quantized models), and underscore the need to integrate security mechanisms into deep learning compilation toolchains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.